Microsoft ECC Root Certificate Authority 2017.crt: CN=Microsoft ECC Root Certificate Authority 2017,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US (Root Certificate, Expiring 2042-07-26) detail info and audit record

 

Page content

CA Certificate Information and Audit Record

This certificate is root certificate used for the issuance of other certificates.

Download certificate through curl:

curl -sSL "http://www.microsoft.com/pkiops/certs/archived/Microsoft%20ECC%20Root%20Certificate%20Authority%202017.crt" --output cert.crt

Download certificate through wget:

wget -q "http://www.microsoft.com/pkiops/certs/archived/Microsoft%20ECC%20Root%20Certificate%20Authority%202017.crt" --output-document=cert.crt

CA Certificate Detail Information

Use openssl x509 to decode DER certificate to get detail information:

openssl x509 -in cert.crt -inform der -text -noout

Use openssl x509 to decode PEM certificate to get detail information:

openssl x509 -in cert.crt -inform pem -text -noout

Decoded detail certificate information:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            71:76:7e:8d:58:e4:fc:96:49:c6:3e:fb:cf:3a:bd:a7
    Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Root Certificate Authority 2017
        Validity
            Not Before: Jul 26 22:22:53 2017 GMT
            Not After : Jul 26 22:31:47 2042 GMT
        Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Root Certificate Authority 2017
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub: 
                    04:d4:bc:3d:02:42:75:41:13:23:cd:80:04:86:02:
                    51:2f:6a:a8:81:62:0b:65:cc:f6:ca:9d:1e:6f:4a:
                    66:51:a2:03:d9:9d:91:fa:b6:16:b1:8c:6e:de:7c:
                    cd:db:79:a6:2f:ce:bb:ce:71:2f:e5:a5:ab:28:ec:
                    63:04:66:99:f8:fa:f2:93:10:05:e1:81:28:42:e3:
                    c6:68:f4:e6:1b:84:60:4a:89:af:ed:79:0f:3b:ce:
                    f1:f6:44:f5:01:78:c0
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Subject Key Identifier: 
                C8:CB:99:72:70:52:0C:F8:E6:BE:B2:04:57:29:2A:CF:42:10:ED:35
            1.3.6.1.4.1.311.21.1: 
                ...
            X509v3 Certificate Policies: 
                Policy: X509v3 Any Policy
                Policy: 1.3.6.1.4.1.311.76.509.1.1
                  CPS: http://www.microsoft.com/pkiops/Docs/Repository.htm

    Signature Algorithm: ecdsa-with-SHA384
         30:65:02:30:1a:11:55:61:19:fd:28:99:61:e2:2b:42:f3:1d:
         41:35:f3:49:ac:3a:79:e2:a5:60:1c:36:90:49:de:7f:5d:33:
         11:4e:c2:43:8d:b1:03:56:98:59:5d:a1:e9:1e:04:d6:02:31:
         00:c3:c6:be:1c:c3:7c:e7:f2:cd:59:43:6e:2a:8a:cf:7e:c4:
         44:4e:03:7a:92:11:3c:6a:45:b9:85:1e:54:cd:3a:1a:9e:90:
         b2:5e:c0:b9:8a:ea:be:8c:74:11:65:0b:02

CA Certificate in PEM Format

Use openssl x509 to convert certificate from DER format to PEM format:

openssl x509 -in cert.crt -inform der

Converted PEM format certificate:

-----BEGIN CERTIFICATE-----
MIIDEjCCApigAwIBAgIQcXZ+jVjk/JZJxj77zzq9pzAKBggqhkjOPQQDAzCBjDEL
MAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24xEDAOBgNVBAcTB1JlZG1v
bmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlvbjE2MDQGA1UEAxMtTWlj
cm9zb2Z0IEVDQyBSb290IENlcnRpZmljYXRlIEF1dGhvcml0eSAyMDE3MB4XDTE3
MDcyNjIyMjI1M1oXDTQyMDcyNjIyMzE0N1owgYwxCzAJBgNVBAYTAlVTMRMwEQYD
VQQIEwpXYXNoaW5ndG9uMRAwDgYDVQQHEwdSZWRtb25kMR4wHAYDVQQKExVNaWNy
b3NvZnQgQ29ycG9yYXRpb24xNjA0BgNVBAMTLU1pY3Jvc29mdCBFQ0MgUm9vdCBD
ZXJ0aWZpY2F0ZSBBdXRob3JpdHkgMjAxNzB2MBAGByqGSM49AgEGBSuBBAAiA2IA
BNS8PQJCdUETI82ABIYCUS9qqIFiC2XM9sqdHm9KZlGiA9mdkfq2FrGMbt58zdt5
pi/Ou85xL+WlqyjsYwRmmfj68pMQBeGBKELjxmj05huEYEqJr+15DzvO8fZE9QF4
wKOBvDCBuTAOBgNVHQ8BAf8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4E
FgQUyMuZcnBSDPjmvrIEVykqz0IQ7TUwEAYJKwYBBAGCNxUBBAMCAQAwZQYDVR0g
BF4wXDAGBgRVHSAAMFIGDCsGAQQBgjdMg30BATBCMEAGCCsGAQUFBwIBFjRodHRw
Oi8vd3d3Lm1pY3Jvc29mdC5jb20vcGtpb3BzL0RvY3MvUmVwb3NpdG9yeS5odG0A
MAoGCCqGSM49BAMDA2gAMGUCMBoRVWEZ/SiZYeIrQvMdQTXzSaw6eeKlYBw2kEne
f10zEU7CQ42xA1aYWV2h6R4E1gIxAMPGvhzDfOfyzVlDbiqKz37ERE4DepIRPGpF
uYUeVM06Gp6Qsl7AuYrqvox0EWULAg==
-----END CERTIFICATE-----

Decode PEM Certificate online

Download PEM Certificate

Also see Top 1 Millions Domains CA Certificate List


Page version: e13a7e3f2 2023-05-06